SQL Injection Vulnerability in Microsoft SQL Server
CVE-2026-26116
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2026-26116?
A vulnerability exists in Microsoft SQL Server that allows an authorized attacker to perform an SQL injection. This could enable the attacker to execute arbitrary SQL commands, potentially leading to elevated privileges over the network, thus compromising the security of the database and sensitive data within. Users are encouraged to apply the latest security patches to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Microsoft SQL Server 2025 (CU 2) x64-based Systems 17.0.0.0 < 17.0.4020.2
Microsoft SQL Server 2025 for x64-based Systems (GDR) 17.0.1050.2 < 17.0.1105.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved